Box Info OS Windows Difficulty Easy As is common in real life Windows pentests, you will start this box with credentials for the following account: rose / KxEPkKe6R8su
Nmap root@kali: /home/kali/EscapeTwo ➜ nmap EscapeTwo.htb -sV -Pn -T4 Nmap scan report for EscapeTwo.htb PORT STATE SERVICE VERSION 53/tcp open domain Simple DNS Plus 88/tcp open kerberos-sec Microsoft Windows Kerberos 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: sequel.htb0., Site: Default-First-Site-Name) 445/tcp open microsoft-ds? 464/tcp open kpasswd5? 593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 636/tcp open ssl/ldap Microsoft Windows Active Directory LDAP (Domain: sequel.htb0., Site: Default-First-Site-Name) 1433/tcp open ms-sql-s Microsoft SQL Server 2019 15.00.2000 3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: sequel.htb0., Site: Default-First-Site-Name) 3269/tcp open ssl/ldap Microsoft Windows Active Directory LDAP (Domain: sequel.htb0., Site: Default-First-Site-Name) Service Info: Host: DC01; OS: Windows; CPE: cpe:/o:microsoft:windows SMB User Crack root@kali: /home/kali/EscapeTwo ➜ crackmapexec smb escapetwo.htb -u "rose" -p "KxEPkKe6R8su" --rid-brute | grep SidTypeUser SMB EscapeTwo.htb 445 DC01 500: SEQUEL\Administrator (SidTypeUser) SMB EscapeTwo.htb 445 DC01 501: SEQUEL\Guest (SidTypeUser) SMB EscapeTwo.htb 445 DC01 502: SEQUEL\krbtgt (SidTypeUser) SMB EscapeTwo.htb 445 DC01 1000: SEQUEL\DC01$ (SidTypeUser) SMB EscapeTwo.htb 445 DC01 1103: SEQUEL\michael (SidTypeUser) SMB EscapeTwo.htb 445 DC01 1114: SEQUEL\ryan (SidTypeUser) SMB EscapeTwo.htb 445 DC01 1116: SEQUEL\oscar (SidTypeUser) SMB EscapeTwo.htb 445 DC01 1122: SEQUEL\sql_svc (SidTypeUser) SMB EscapeTwo.htb 445 DC01 1601: SEQUEL\rose (SidTypeUser) SMB EscapeTwo.htb 445 DC01 1607: SEQUEL\ca_svc (SidTypeUser) SMB File Leak [root@kali] /home/kali/EscapeTwo ❯ smbclient -L //10.10.xx.xx -U rose Password for [WORKGROUP\rose]: Sharename Type Comment --------- ---- ------- Accounting Department Disk ADMIN$ Disk Remote Admin C$ Disk Default share IPC$ IPC Remote IPC NETLOGON Disk Logon server share SYSVOL Disk Logon server share Users Disk 在这个Accounting Department中存在表格文件
...